"incognito mode makes you anonymous"
loreprivacyweb dev
Private browsing deletes local history and cookies when the window closes - nothing more. Websites, employers, and providers see you exactly as before.
Chrome's own Incognito splash text lists these limits; a US class action over Incognito-mode tracking ended with Google agreeing in 2024 to destroy billions of collected records.
Private browsing prevents a browser from storing history, cookies and form data locally after the session ends. That is the entire guarantee, it is stated accurately in the browser's own opening screen, and it is routinely understood as something much larger.
What it does not do is anything about the network. The internet provider still sees the connections, the employer's proxy still logs them, the destination site still receives an address and a fingerprint, and any account you sign into identifies you completely. The protection is against someone with local access to the same machine afterwards, which is a real threat model and a narrow one.
The gap between the guarantee and the perception has been measured repeatedly and is wide, which raises a genuine design question about naming. Incognito and private are words that promise more than the feature delivers, and users acting on the stronger belief take risks they would not otherwise take. That makes it a good example of how a feature name can become a security problem: the technology works exactly as documented, and the documentation is not what people read.
Disputed / commonly mistold A popular version of this story is inaccurate - see the note above.
Also known as: private browsing myth
Sources
- Google Chrome Incognito mode disclosure text
- Brown v. Google settlement, N.D. Cal. (2024)